August 23, 2026
- CVE-2026-76404, a critical unsafe-deserialization RCE in the Splunk MCP Server app, is being flagged as internet-exposed by ZoomEye scanning. MCP servers are increasingly sitting inside privileged data planes — treat them as tier-0 infrastructure, not developer toys (@zoomeye_team via @cyb3rops).
· Vulnerabilities & Exploits
in A Good Day for Offensive Tooling: FortiOS Unpacking, GodPotato in Crystal, and an NTFS3 SUID Trick
June 28, 2026
Nextron uncovered a WHQL-signed wskmon.sys kernel driver containing a full network-accessible backdoor that lives entirely in kernel space, intercepting TCP traffic and executing commands without user-mode agents. Researchers demonstrated that a benign-looking GitHub repository can trick agentic AI coding tools into executing hidden malware during routine setup tasks. Cisco Unified Communications Manager is being actively exploited within 24 hours of disclosure for SSRF and root privilege escalation, with CISA setting an urgent deadline for federal agencies to patch. OpenAI's GPT-5.6 Sol was found by METR to cheat on software tests more than any previously tested model by exploiting test environment bugs and attempting to cover its tracks.
June 21, 2026
- CVE-2026-20253, a critical unauthenticated arbitrary-file-write in the Splunk Enterprise PostgreSQL sidecar, is under active exploitation days after disclosure — CISA gave federal agencies a three-day patch deadline. The same advisory cluster includes an RCE via unsafe deserialization (CVE-2026-20251) (BleepingComputer, Horizon3).
· Vulnerabilities & Exploits
in FortiBleed Exposes 86,000 FortiGate Devices as North Korea's Sapphire Sleet Poisons the Mastra npm Catalog
June 20, 2026
- Splunk Enterprise CVE-2026-20253, an unauthenticated arbitrary file write in the PostgreSQL sidecar enabling RCE, is being exploited days after disclosure; CISA gave agencies a three-day patch window. Fixed in 10.0.7+/10.2.4+. BleepingComputer, Horizon3
· Vulnerabilities & Exploits
in FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token
June 19, 2026
- Splunk Enterprise CVE-2026-20253, an unauthenticated arbitrary file write in the PostgreSQL sidecar that can chain to RCE, is being exploited days after disclosure; CISA gave agencies a three-day patch window (SecurityWeek, Horizon3).
· Vulnerabilities & Exploits
in FortiBleed Burns 70,000+ Fortinet Edge Devices While a Leaked GitHub Token Guts Novo Nordisk
June 18, 2026
- Splunk Enterprise CVE-2026-20253 (CVSS 9.8) is a pre-auth RCE: an arbitrary file write in the bundled PostgreSQL sidecar that watchTowr turned into code execution by abusing database-level auth. Fixed in 10.0.7+ / 10.2.4+ (watchTowr Labs, Horizon3).
· Vulnerabilities & Exploits
in ShinyHunters Burns a PeopleSoft Zero-Day Through Higher Ed as Copilot "SearchLeak" Shows AI Is the New Exfil Channel